Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.66%
  • Published 30.06.2011 16:55:05
  • Last modified 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and Thunderbird before 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code...

  • EPSS 4.61%
  • Published 30.06.2011 16:55:05
  • Last modified 11.04.2025 00:51:21

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multip...

  • EPSS 0.35%
  • Published 30.06.2011 16:55:05
  • Last modified 11.04.2025 00:51:21

CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass inten...

  • EPSS 2.45%
  • Published 30.06.2011 16:55:04
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial ...

  • EPSS 2.45%
  • Published 30.06.2011 16:55:04
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues t...

Exploit
  • EPSS 0.15%
  • Published 30.06.2011 15:55:04
  • Last modified 11.04.2025 00:51:21

The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.

Exploit
  • EPSS 0.61%
  • Published 30.06.2011 15:55:03
  • Last modified 11.04.2025 00:51:21

Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack invo...

Exploit
  • EPSS 0.43%
  • Published 06.06.2011 19:55:01
  • Last modified 11.04.2025 00:51:21

The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untruste...

  • EPSS 4.22%
  • Published 07.05.2011 18:55:01
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.

Exploit
  • EPSS 0.52%
  • Published 07.05.2011 18:55:01
  • Last modified 11.04.2025 00:51:21

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the au...